The Telephone Preference Service is a UK opt-out register that people use to reduce unsolicited marketing calls. Organisations must screen call lists against it before making marketing calls, unless a lawful exception applies. It is a practical compliance control for outbound telephone campaigns and call governance.
What the Telephone Preference Service actually does
The Telephone Preference Service, or TPS, is a UK opt-out register for people who do not want unsolicited marketing calls. Its security and governance value is practical: it creates a screening control that helps outbound callers reduce avoidable nuisance, respect consent preferences, and avoid calling numbers that should be suppressed before a campaign goes live.
That makes TPS more than a consumer convenience. For call centres, sales teams, and outsourced telemarketing partners, it is a data-quality and compliance checkpoint that sits in front of the calling process. Organisations that run campaigns at scale need to treat it as a list hygiene control, not as a one-time legal checkbox.
Where TPS fits in outbound call governance
TPS belongs in the broader control stack for lawful outbound telephone marketing. It does not replace consent management, legitimate-interest assessment, internal suppression lists, or contract controls with third parties; it simply helps determine whether a number should be excluded from marketing outreach. That means its role is strongest when the organisation is building or updating calling lists, onboarding a campaign vendor, or auditing a dialling workflow.
In practice, teams should think of TPS as part of a suppression and eligibility workflow. If a number appears on the register, the campaign process should be able to prevent that number from being dialled for marketing purposes unless a lawful exception applies. If the control is missing or poorly timed, the business can still create exposure even when the campaign itself is otherwise well-intentioned.
Because the register only governs a specific calling context, definitions and exceptions matter. A compliant process needs to distinguish marketing calls from service calls, customer-care calls, and other permitted contact categories rather than applying a blanket rule to every outbound call type.
Why accuracy and timing matter
The value of TPS depends on when the list is checked and how reliably the suppression result is applied. A stale extract, an incomplete screening step, or a downstream vendor that uses an unscreened list can undermine the control even if the organisation technically “uses TPS”. That is why call governance should include clear ownership for screening, list refresh timing, vendor instructions, and evidence that suppression took place before calling.
It is also important to keep TPS separate from marketing strategy. A team may be tempted to treat it as a minor administrative task, but the operational consequence of getting it wrong is repeated unwanted contact, customer friction, and a control failure that is easy to see after the fact. NHI Mgmt Group’s Ultimate Guide to Non-Human Identities notes that 91.6% of secrets remain valid five days after notification, which is a useful reminder that governance controls fail when revocation or suppression is too slow to keep up with operational reality.
When TPS matters most in practice
TPS matters most where outbound calling is frequent, outsourced, or automated. High-volume campaigns amplify small process errors, and third-party diallers can create blind spots if they are not contractually required to apply the register before launch. The control is also important where organisations reuse data across different campaigns, because a number that was once valid to call may later become suppressed and should stay suppressed.
The practical takeaway is simple: if you own outbound marketing, TPS should be embedded into list preparation, vendor oversight, and audit evidence. If it is treated as a one-off lookup instead of an ongoing suppression control, the organisation is likely to drift into non-compliant calling patterns even when the campaign content itself is otherwise legitimate.
Risk and Threat Considerations
TPS failures create exposure through repeated unwanted contact, poor suppression discipline, and weak oversight of outsourced calling. The main risk is not technical compromise, but governance breakdown: an organisation can keep calling numbers it should have excluded, especially when list hygiene, vendor processes, or refresh timing are inconsistent.
Failure mechanism: marketing lists are screened too early, not refreshed, or not enforced consistently by every calling system or supplier, so suppressed numbers remain reachable.
Impact: the organisation can generate avoidable complaints, regulatory scrutiny, reputational harm, and campaign waste while continuing to expose recipients to calls they expected to avoid.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 — Access Permissions Management | TPS is a suppression control that governs who may be contacted by a campaign. |
| GV.RM-01 — Risk Management Strategy | TPS requires governance over campaign eligibility, third-party use, and compliance risk. | |
| GV.OV-01 — Policy Oversight | TPS needs policy-backed oversight so screening is consistently applied across campaigns and vendors. | |
| Recommendation — Apply PR.AC-4 to enforce suppression rules before outbound marketing calls are placed. Include TPS screening in your outbound-calling risk strategy and assign accountable ownership. Define policy oversight for TPS checks and verify vendors follow the same suppression rules. | ||
| CIS Controls v8 | 6.3 — Access Grants and Revocations | TPS screening functions like revoking an outbound contact path for opted-out recipients. |
| Recommendation — Use Control 6.3 to remove suppressed numbers from outbound call lists before dialing. | ||
Practitioner Guidance
Governance implication: treat TPS screening as a mandatory control point in the outbound calling workflow, with clear ownership for who checks, when it is checked, and how suppression is evidenced. The control should be applied before a campaign starts and again whenever lists are reused or updated.
Common misunderstanding: having a TPS process is not the same as having a compliant process. The real test is whether the screening result is consistently enforced across in-house teams, outsourced diallers, and any recycled data sets.